US9871818B2

Managing workflows upon a security incident

Summary by NHIP

Dynamic SLA Management

The system identifies a rule set and default service level agreement for a security incident, then modifies the agreement based on environmental characteristics like asset criticality ratings. Administrators receive updated action hierarchies and time periods, providing input to select actions or modify recommendations through feedback.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Systems, methods, and software described herein provide for managing service level agreements (SLAs) for security incidents in a computing environment. In one example, an advisement system identifies a rule set for a security incident based on enrichment information obtained for the security incident, wherein the rule set is associated with action recommendations to be taken against the incident. The advisement system further identifies a default SLA for the security incident based on the rule set, and obtains environmental characteristics related to the security incident. Based on the environmental characteristics, the advisement system determines a modified SLA for the security incident.

US9871818B2, drawing sheet 1
Sheet 1 of 8

Term

9.3 yearsleft in the term

Expires 27 December 2035, including 254 days of term adjustment.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

15 claims: 3 independent, 12 dependent

  1. 1
    Broadest claimClaim Score 29, narrow(NHIP)A method of managing service level agreements (SLAs) for security incidents in a computing environment, the method comprising:identifying a rule set for a security incident of the security incidents based on enrichment information obtained for the security incident, wherein the rule set is associated with one or more action recommendations to be taken against the security incident;identifying a default SLA for the security incident based on the rule set, wherein the default SLA comprises a default hierarchy of administrators for the security incident and a default set of one or more time periods for administrator security actions;obtaining environmental characteristics related to the security incident, wherein the environmental characteristics comprise at least a criticality rating of an asset associated with the security incident;determining a modified SLA for the security incident based on the environmental characteristics, wherein the modified SLA comprises a second hierarchy of administrators for the security incident and a second set of one or more time periods for administrator security actions;providing the one or more security actions to administrators based on the modified SLA;and obtaining input from at least one administrator, wherein the input comprises: an action selection of the one or more security actions;or feedback regarding the one or more action recommendations, wherein the feedback comprises modifying the one or more action recommendations, removing an action recommendation from the one or more action recommendations, or deferring action selection to another administrator.
  2. 6
    An apparatus to manage service level agreements (SLAs) for security incidents in a computing environment, the apparatus comprising:one or more non-transitory computer readable media;and processing instructions stored on the one or more computer readable media that, when executed by a processing system, direct the processing system to: identify a rule set for a security incident of the security incidents based on enrichment information obtained for the security incident, wherein the rule set is associated with one or more action recommendations to be taken against the security incident;identify a default SLA for the security incident based on the rule set, wherein the default SLA comprises a default hierarchy of administrators for the security incident and a default set of one or more time periods for administrator security actions;obtain environmental characteristics related to the security incident, wherein the environmental characteristics comprise at least a criticality rating of an asset associated with the security incident;determine a modified SLA for the security incident based on the environmental characteristics, wherein the modified SLA comprises a second hierarchy of administrators for the security incident and a second set of one or more time periods for administrator security actions;provide the one or more security actions to administrators based on the modified SLA;and obtain input from at least one administrator, wherein the input comprises: an action selection of the one or more security actions;or feedback regarding the one or more action recommendations, wherein the feedback comprises modifying the one or more action recommendations, removing an action recommendation from the one or more action recommendations, or deferring action selection to another administrator.
  3. 11
    An advisement system to manage service level agreements (SLAs) for security incidents in a computing environment with a plurality of assets, the advisement system comprising:one or more non-transitory computer readable media;a processing system operatively coupled to the one or more non-transitory computer readable media;and processing instructions stored on the one or more computer readable media that, when executed by a processing system, direct the processing system to: identify a rule set for a security incident of the security incidents based on enrichment information obtained for the security incident, wherein the rule set is associated with one or more action recommendations to be taken against the security incident;identify a default SLA for the security incident based on the rule set, wherein the default SLA comprises a default hierarchy of administrators for the security incident and a default set of one or more time periods for administrator security actions;obtain environmental characteristics related to the security incident, wherein the environmental characteristics comprise at least a criticality rating of an asset associated with the security incident;determine a modified SLA for the security incident based on the environmental characteristics, wherein the modified SLA comprises a second hierarchy of administrators for the security incident and a second set of one or more time periods for administrator security actions;provide the one or more security actions to administrators based on the modified SLA;and obtain input from at least one administrator, wherein the input comprises: an action selection of the one or more security actions;or feedback regarding the one or more action recommendations, wherein the feedback comprises modifying the one or more action recommendations, removing an action recommendation from the one or more action recommendations, or deferring action selection to another administrator.